Skip to content

Week of September 21 -- 27, 2026

The grove→project rename reached its breaking phase this week. Legacy grove routes, CLI flags, API keys, event topics, container labels, environment variables and hub↔broker wire fields were all removed, and on-disk grove state now migrates automatically. Hub and broker must now be upgraded together. Alongside the rename, a broad authorization sweep closed several cross-member and cross-project exposure paths. Single-node VM deployment became headless, self-updating and Vertex-ready out of the box, and the new persistent terminal workspace gained shareable layouts and auto-reconnect.


Over three days the remaining grove aliases were removed from every layer. That covers /api/v1/groves routes, --grove flags, scion grove commands, groveId-style request and response keys, scion.grove.* topics, scion.grove* container labels, SCION_GROVE* agent env vars, and the hub↔broker HTTP, heartbeat and websocket protocols. On startup, the CLI, hub and broker move ~/.scion/groves and ~/.scion/grove-configs to their project equivalents, leaving symlinks behind. They also rewrite .scion/grove-id and hub.grove_id in place. Hub and broker versions can no longer be mixed, and agents created before the rename should be restarted. The new grove removal migration guide lists every change and its replacement.

A wide security sweep closed several exposure paths. Project owners and admins could attach to members’ agents and read their user-scoped secrets; agent.lifecycle is now split from agent.attach to stop this. Duplicate legacy grove.<projectId>.* SSE subjects let any authenticated session read every project’s live events; they are removed, and SSE authorization now uses a deny-by-default allowlist. Six template handlers had no authorization checks, and broker agent delete could remove a same-slug agent in another project. Both are fixed. Resource, workspace, agent and broker-ownership routes now authorize at a single dispatcher, and user- and project-scoped skills, templates and harness configs are readable only within their scope. Project file handlers and attachment ingest now use os.Root to block symlink traversal.

The single-node VM tier gained binary auto-update. The Hub now checks for updates according to a configured deployment tier, release channel and update policy, using LATEST.json and GitHub Releases for binary installs. deploy.sh --config pre-answers every wizard prompt, which enables agent-driven, non-interactive installs from a new agent deployment runbook. It also works in hardened GCP orgs (no default VPC, Shielded VM required, default compute SA disabled). A hub-wide default GCP identity (block, passthrough or assign) means a fresh VM can run Vertex AI inference without manual setup.

A multi-pane terminal workspace landed behind the terminal_workspace feature flag (off by default). It supports cross-tab ownership, reconnect controls and scoped PTY cleanup. Layouts are encoded in the URL, so multi-pane configurations can be shared and bookmarked. A new PTY close-code contract tells a clean detach apart from an ended session, a missing agent or a retriable drop. Together with keepalive pings, this lets panes reconnect automatically behind a “Reconnecting…” overlay.


  • Hub and broker must be upgraded together (#2015, #2017): Grove-named fields are removed from hub↔broker wire types, the heartbeat payload and the broker websocket protocol. /api/v1/workspace/grove-upload is replaced by /api/v1/workspace/project-upload.
  • Hub API grove keys removed (#1999, #1997, #1958, #1968, #1944): /api/v1/groves[/…] returns 404. Requests and responses no longer carry groveId, groveName, grove or groves, including in SSE payloads and store models. "grove" is rejected as a scope with 400. Resolved secrets report source: "project". Existing scope='grove' rows are normalized on boot.
  • Grove CLI commands, flags and output keys removed (#1938, #1957, #1954, #1960, #1961, #1971): scion grove, scion hub groves, scion config cd-grove, every --grove flag, the grove: template-scope prefix and grove_id config keys are gone. --json output emits only project* keys.
  • Grove topics, labels and env vars dropped (#2001, #2012, #1995, #2016, #1962): Only scion.project.* topics are routed, and containers carry only scion.project* labels. Agents no longer receive or read SCION_GROVE_ID, SCION_GROVE or SCION_GROVE_PATH, and SCION_HUB_GROVE_ID is ignored. Setting a legacy variable prints a one-time warning. Restart agents created before the rename.
  • a2a-bridge and fs-watcher grove aliases removed (#1990): The a2a-bridge silently ignores a groves: config key, so a config that uses only groves: starts with zero projects. Rename it to projects:.
  • Agent permission model split (#1838): agent.lifecycle (start/stop/suspend/restart/restore) is separated from agent.attach. Project owners and admins keep lifecycle and messaging rights on members’ agents but lose attach and port_access. Project-owner and project-admin roles move to revision 3.
  • Per-broker agent limit (#1902, #1946): max_agents_per_broker (default 12, overridable per broker) is checked before agent creation. Previously, creating agents past capacity could crash the broker host. Only running agents count toward the limit.
  • GCP --project renamed to --gcp-project (#1937): Applies to scion project service-accounts add and scion hub secret migrate. There is no alias, but old invocations print a targeted hint.
  • visibility field removed (#1916, #1929): The field is gone from agents, templates, harness configs and skills. Access depends only on scope and grants.
  • Broker error code renamed (#1923): global_grove_disabled is now global_project_disabled.
  • Copilot and grok-build telemetry env reserved (#2018): Agents fail to start if the runtime env overrides COPILOT_OTEL_*, GROK_TELEMETRY_* or GROK_EXTERNAL_OTEL.
  • Cross-project SSE leak closed (#1970, #1809): Legacy grove publish subjects are removed, SSE authorization uses an explicit allowlist, and project.> wildcard subscriptions expand only to projects the caller is authorized for.
  • Cross-member secret exposure (#1838): Owners and admins can no longer attach, exec, read env or reach ports on other members’ agents.
  • Template authorization (#1804, #1881): Six template handlers gained missing authorize() gates. Before this, any authenticated user could modify any template, including global ones. The template files subtree now checks access on the specific template and validates paths.
  • Hub route authorization (#1886, #1882, #1926): Agent status, harness config, project GitHub settings, project workspace (files, archive, WebDAV, sync) and project agent routes now authorize once in a dispatcher. Chat search returns DM threads only to their participants.
  • Scope boundary on resource reads (#1912, #1936): User- and project-scoped skills, templates and harness configs are readable only by their owner, project members and hub admins. Template resolution and cloning are scope-checked.
  • Cross-project agent delete (#1875): Broker delete is scoped to the requested project on every runtime and fails closed on ambiguous matches.
  • Symlink traversal hardening (#1850, #1876): Project file handlers and attachment ingest resolve paths through os.Root, so symlinks that point outside the served directory are refused.
  • Broker ownership and project updates (#1982, #1969, #1949, #1945): Broker re-registration and secret rotation require broker ownership. Implicit project mutations (register, provider link, auto-link) require update access.
  • Harness telemetry redaction bypass (#2018): Copilot and grok-build now always export OTel through the local sciontool receiver, so redaction and identity stamping apply.
  • Credential handling (#1894, #1966, #1942, #1870): The reset-auth token is passed over stdin instead of argv. The transport service account is never provisioned as a hub user. GitHub webhooks are rejected when no secret is configured. Broker failure reasons are sanitized and truncated to 512 bytes.
  • Skill download capability URLs (#1874): Local-storage Hubs issue 15-minute HMAC-signed URLs bound to the exact skill, version and path, which fixes 401s on broker skill downloads.
  • Global skill authoring permission (#1803, #1807): The new skill.create_global permission and global-catalog-author role allow global catalog writes without full hub-admin authority.
  • Path and network hardening (#1998, #1979): Agent names are validated as single clean path elements. The single-node VM’s IAP SSH firewall rule targets only the hub VM.
  • Generic JWT proxy auth provider (#1858, #1863): auth.proxy.provider: jwt supports bespoke auth proxies. Keys can come from PEM files, a JWKS URL (with proactive refresh and last-good fallback) or a JWKS file, with issuer/audience validation and OIDC claim mapping.
  • Google bearer pass-through for A2A (#1880): The Hub accepts Google ID tokens and OAuth access tokens directly, with per-issuer trust settings. The A2A bridge gains a hubBearer scheme. The GE token exchange is deprecated.
  • Hub-default GCP identity (#1906, #1927, #1915, #1899, #1897, #1883): Agent Defaults gains a hub-wide GCP identity mode, which also applies to scheduled dispatch. Single-node VMs default to passthrough and seed Vertex AI env vars.
  • Scheduled agent identity (#1872): Scheduled agents get CreatorName and the project-default GCP identity, subject to the same checks as manual creation.
  • Persistent terminal workspace (#1795): Multi-pane workspace with cross-tab ownership, reconnect controls and scoped PTY cleanup, behind the terminal_workspace flag.
  • Auto-reconnect (#1953, #1973, #1984, #1959, #1993): The PTY close-code contract (1000, 4410, 4404, 4503), broker-side classification of why each attach ended, keepalive pings and a single reconnect attempt when the pane is next in front.
  • URL layout encoding (#1816): Multi-pane layouts persist in the URL, so they can be shared and bookmarked.
  • Layout and theming fixes (#1805, #1812, #1806, #2011): Layouts are preserved during navigation. Stale focus outlines are removed. Tmux titles sync on attach. The terminal pane now follows light-mode theme tokens.
  • Honest message delivery (#1868, #1895, #1893, #1892, #1940, #1903): Messages to non-running agents fail with “Agent unreachable” or DELIVERY_FAILED instead of showing “Delivered”. Broker flush failures are retried three times and reported to senders live. Failed messages are purged after 7 days.
  • Cross-project messaging cleanup (#1808): A 4-phase pass covering admission-gap authorization, truthful delivery, a converged send API and acceptance tests.
  • Group conversations (#1846, #1864): CLI-created groups appear in web chat. The default agent is kept consistent across both stores, and agents dispatched into a group are tracked as participants.
  • Browser notification chime (#1861): A two-tone chime plays when messages from other users arrive, with global and per-project toggles.
  • Chat navigation (#1932, #1911, #1910, #1871): Threads with unreads open at the “New messages” divider. Inter-agent messages get day dividers and a two-line layout. The thread-default agent is listed first.
  • Touch and mobile (#1857, #1859): On touch devices, Enter inserts a newline, and the message context menu opens on tap.
  • Chat fixes (#1794, #1826, #1829, #1913, #1921, #1939, #1855, #1856): File-path auto-linking and resolution fixes, one-keystroke @mention deletion, fixed promote-DM-to-thread errors, and an end to members-sidebar flicker.
  • scion reincarnate (#1918): Restarts an agent on the same row with a freshly derived config, image and harness config, through an async hub worker with dry-run support.
  • Best-effort resume (#1900): forceResume and a “Resume (best effort)” button continue the harness session of an agent in the error phase.
  • Workspace recreation on start (#2026): On runtimes such as Kubernetes that don’t keep workspaces across a stop, start sends the clone config needed to recreate the workspace.
  • Broker quota accounting (#1951, #1967, #1975, #1978): Reservations are now released correctly across failed starts, failed creates, stop/suspend and timed-out DM wakes.
  • Start and restart reliability (#1941, #1891, #1890, #1964, #1976, #1972, #1988, #1845): Skills resolve as the agent’s creator. Model aliases resolve on resume. Transient docker ps failures are retried. Container lookup failures return 5xx instead of false success.
  • Leaked sandboxes on dispatch timeout (#1908): The hub cancels timed-out dispatches, and Docker, Podman and Apple container runtimes roll back any container that started.
  • scion project status (#1782): A new command (alias health) shows per-project agent metrics. (Contributor: G. Hussain Chinoy)
  • Agents can read skills (#1950): Agents can list and read hub-catalog skills and skills from their own project.
  • Binary auto-update (#1824): New maintenance config fields deployment_tier, release_channel, update_policy and check_interval_hours. The check-updates API dispatches by tier.
  • Headless deploy (#1823, #1862): deploy.sh --config pre-answers all prompts. The config format is now JSON, which removes the PyYAML dependency.
  • Hardened GCP orgs (#2004, #1980): Deploy works under common org policies using a zero-role proxy service account, and reuses or creates a subnet-scoped Cloud NAT.
  • Deploy friction-log sweep (#1836, #1827, #1867): Twelve fixes from live runbook testing, plus an IAP proxy image built on the VM so deploys no longer depend on GCS.
  • Hybrid tier NFS shared directories (#1849, #1877, #1889): server.shared_dir_storage backs shared directories with NFS for Docker and Kubernetes agents. Operations go through a confined resolver with hardened modes and ACLs, and a project’s NFS tree is removed when the project is deleted.
  • Agent hub endpoint override (#1925): server.hub.agent_endpoint overrides only the SCION_HUB_ENDPOINT given to agents.
  • Profile timezone (#1822, #1884): Profiles have an IANA timezone setting, editable in web settings, which is injected into agent containers as TZ.
  • Hub boot on fresh Postgres (#2028): A migration hook no longer aborts the transaction on a new database.
  • Unwritable NFS workspaces on Kubernetes (#2027): The workspace-provision init container now runs for NFS-backed agents, so /workspace is writable.
  • Docker agent listing (#1888): docker ps requests only the fields it parses, which avoids size-computation races that broke listing and delivery.
  • Doctor fixes (#1924, #1780): sciontool doctor no longer revokes the agent’s token. scion doctor passes stored hub auth tokens.
  • Default templates and harness configs (#1898, #1905): Embedded defaults load at bootstrap, so creates no longer return 502.
  • Identity and rename consistency (#2019, #2014, #1920, #1919, #1917): Agent identity keys are unique per project. Agent operations work for paths recorded before the directory rename. chat-app accepts project topics again.
  • Container images (#1831, #1839, #2025): core-base moves to Debian 13 with a vendored git 2.55.0. sciontool version reports the version and commit, and images carry the OCI revision label.
  • Cloud Run Instances runtime (#1817): Fixes project discovery, instance-ID length, PTY support and hub endpoint resolution.
  • Postgres fixes (#1796, #1810): Broker labels and annotations migrate to jsonb, and CTE seed parameters are cast to uuid. (Contributor: sal-m2026)
  • Responsive header redesign (#1820, #1802, #1834): Three-tier layout (full labels, icon-only, hamburger dropdown) with a centered, labeled mode switcher.
  • Project page improvements (#1860, #1835, #1833, #1865): The agents section can be expanded or collapsed. The Create Project button is restored for users with no projects. Nested scrollbars are removed.
  • Toast and card fixes (#1815, #1837): Fixes a Shoelace toast removal race and long agent names overflowing cards.
  • SQLite hub test job (#1904, #2034): A parallel job runs the roughly 73% of pkg/hub tests that the no_sqlite build never compiled.
  • Hub test suite fixes (#1799): Fixes 25 previously failing pkg/hub tests.
  • Grove regression guards (#2000, #1948): A command-tree walk and a case-insensitive compat-literal guard fail the build on any reintroduced “grove” terms.
  • deploy.sh test harness (#1977): An offline gcloud stub and test runner, wired into CI.
  • Release automation (#1830, #1887, #1901): Nightly manifest updates merge through PRs with retries, and conflicted PRs show a failing mergeability check.
  • Grove removal migration guide (#1962, #1996): A reference page mapping every removed grove name to its replacement.
  • Agent deployment runbook (#1825, #1866, #1851): An agent-oriented runbook for the single-node VM tier covering GCP preflight, conversational prompts, config generation and troubleshooting.
  • Grove wording cleanup (#1922): READMEs, CLI help and schema descriptions now say “project” instead of “grove”.
  • chat-app slash commands (#1952): The README now lists admin commands under /scionAdmin.